Find out what the EU AI Act requires of you. In two weeks, with the article behind every finding.
Transparency duties under Article 50 have been in force since 2 August 2026. Machine-readable marking of AI-generated content is due 2 December 2026. High-risk logging obligations follow in 2027. If your product has users in the EU, this applies to you wherever your company sits.
This assessment tells you which obligations apply, where you fall short, and what to do about it. Fixed scope. Fixed price. Written report.
Not legal advice. Not a certification. Your counsel makes the legal determinations; this report gives them something to determine from.
Software companies of roughly 10 to 200 people that ship an AI feature (a chatbot, generated content, decision support) to users in the EU, and have nobody whose job is compliance.
Put plainly: if you have a legal department and a compliance platform, you do not need this. If you have an engineer who was handed “compliance” on top of their real job, you do.
Nine deliverables, delivered as one written report.
- Scope and system inventory. Every AI system you operate, what it does, and where its output goes.
- Role determination. Provider, deployer, importer or distributor, per system, with reasoning.
- Obligation mapping. Which articles apply to which system, and from what date.
- Risk classification. Prohibited, high-risk, limited or minimal, per system.
- Gap analysis. What each applicable article requires, what you have, what is missing.
- Record-keeping review. What you log today against what Article 12 will require.
- FRIA starter draft. A fundamental rights impact assessment template pre-filled with your systems, where one is required.
- Remediation plan. Ordered by deadline and effort, with owners.
- Evidence appendix. Signed evidence records for the checks performed, verifiable offline with our published key.
Plus a walkthrough call when the report is delivered, and 30 days of email follow-up.
Before the engagement. A 30-minute scoping call. You describe what you ship and where. I confirm the assessment fits and what access I need. If it does not fit, I say so on the call.
Week one. Inventory and role determination. Short written questions to your team, one hour of interviews, read-only access to whatever shows me what the systems actually do.
Week two. Gap analysis, remediation plan, evidence appendix. Draft report to you by day 10 for factual corrections.
Delivery. Final report, walkthrough call, 30 days of follow-up by email.
Timing: an engagement signed by 15 November 2026 delivers before 2 December.
What this is not.
- Not legal advice. The report cites the article behind every finding so that your counsel can make the legal determination quickly. It does not make it for them.
- Not a certification. Nothing in the EU AI Act is certified by a two-week assessment, and no vendor should tell you otherwise.
- Not a guarantee of compliance. It is a map of what applies, what is missing, and what to fix.
- Not a penetration test, a model evaluation, or a privacy audit. Those are separate jobs. If you need them, I will say so in the scoping call.
Half on signing, half on delivery of the final report. No hourly billing, no scope creep. If the scoping call shows you need less than this, I will quote something smaller.
We are a Canadian (or US, or UK) company. Does the EU AI Act apply to us?
If the output of your AI system is used by people in the EU, yes. Article 2 applies the Act to providers and deployers outside the EU where the output is used in the Union. Where you are incorporated does not matter.
What actually happened on 2 August 2026?
Most of Article 50 took effect: telling users they are interacting with an AI, labelling deepfakes and synthetic content, and notifying people when emotion recognition or biometric categorisation is used. These are in force now.
What happens on 2 December 2026?
Article 50(2): generative AI systems already on the market before 2 August 2026 must mark their output in a machine-readable way. Systems placed on the market after 2 August already have to.
Is a two-week engagement enough?
For a company of 10 to 200 people with one to a handful of AI features, yes. If the scoping call shows more than that, I will tell you before you sign.
What do we have to provide?
A list of your AI features, one hour of your team's time for interviews, and read-only access to the systems or their documentation. No code changes.
Do we have to use VITNA?
No. The evidence appendix is produced with VITNA and verifies offline with our public key, but nothing in the assessment requires you to keep using it. Many companies do, because the Article 12 logging obligation arrives in 2027 and they would rather start the record now.
Who does the work?
Collin Obey, founder of COSTRINITY, based at Pasqua First Nation, Treaty 4, Saskatchewan. No subcontractors.
Two of these answer a narrower question in a couple of minutes, free and without an account. If one of them settles it, you do not need an assessment.
- Does the 2 December 2026 deadline apply to you? Works out which of the two marking dates you are on.
- Article 50 transparency self-check Which disclosure duties reach you as provider or deployer.
- Verify a signed evidence package yourself The same signatures the evidence appendix is built from, checkable offline with our published key.
- What VITNA sends and stores Exactly what leaves your machine, and what is kept.
Thirty minutes to find out whether this fits.
Or write to hello@costrinity.xyz.
Not legal advice. Not a certification. Your counsel makes the legal determinations; this report gives them something to determine from.